GHSA-g3j4-58mp-3x25

    Dashboard / Vulnerabilities / GHSA-g3j4-58mp-3x25

    GHSA-g3j4-58mp-3x25

    Published: 20 Oct 2025Last Modified: 5 Nov 2025

    Summary: NetBird VPN does not remove the default password of an admin account

    Details: NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin account created by ZITADEL. This issue affects instances installed using vendor's provided script. This issue may affect instances created with Docker if the default password was not changed nor the user was removed. This issue has been fixed in version 0.57.0.

    Affected packages

    Package

    Name: github.com/netbirdio/netbird

    Purl: pkg:golang/github.com/netbirdio/netbird

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.57.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g3j4-58mp-3x25 | CVE-DB